build bd3aee6f | content blog-content@66f2592 · 338 posts | profiles 20 · corpus 309 | 0 skipped | | format
apiVersion: soultec.ch/v1kind: Solutionmetadata: name: endpoint-security/crowdstrike-falcon locale: en labels: capability/endpoint-security: 2.85 capability/security: 2.01 vendor/crowdstrike: 4.36 annotations: source: src/content/solutions/en/endpoint-security/crowdstrike-falcon.md route: /en/solutions/endpoint-security/crowdstrike-falcon/ schema: /nerd/schema/solutions.json markdown: /en/solutions/endpoint-security/crowdstrike-falcon.mdspec: title: CrowdStrike Falcon tags: [endpoint-security, security] vendors: [crowdstrike] summary: >- Endpoint detection and response from CrowdStrike. A lean sensor on the device, analysis in the cloud, and a platform that grows by module. photoNeed: A security console on screen with real alerts in it, being triaged stub: false draft: false kind: product addon: false status: current practice: >- CrowdStrike replaces Carbon Black as our EDR product. We no longer support Carbon Black. practiceReview: false sections: - heading:

What it is

body: | Falcon is CrowdStrike's endpoint platform. A lean sensor supplies the events from the device; the analysis runs in the vendor's cloud. What gets judged is behaviour rather than files: not "do I know this signature", but "why is this process reading another one's memory". - heading:

What it is for

body: | Estates that choose their endpoint security independently of the rest of the stack. Falcon ties you to no platform licence and covers Windows, macOS and Linux with the same sensor. The second point is growth: EDR is one module of several. Identity protection, cloud workloads and threat intelligence come out of the same console when they are needed. - heading:

What to watch

body: | The modules are licensed individually, and the feature set depends on the package you bought. What a quote calls "Falcon" is therefore not always the same Falcon. And as with any EDR: the recording is worth as much as the team looking at it. Where there is none, managed detection and response belongs in the plan from day one.status: corpus: 309 services: - {ref: services/modern-workplace, score: 0.82} - {ref: services/security, score: 0.43} - {ref: services/network, score: 0.20} posts: - {ref: posts/how-to-build-a-test-environment-for-opswat-metadefender-managed-file-transfer, score: 0.44} - {ref: posts/how-to-secure-your-dmz-with-a-proxy, score: 0.44} - {ref: posts/exagrid, score: 0.35} - {ref: posts/vmware-security-advisory, score: 0.29} - {ref: posts/vmware-security-advisory-vmsa-2024-0012, score: 0.29} - {ref: posts/vmware-security-advisory-vmsa-2022-0030, score: 0.29} neighbours: - {ref: solutions/endpoint-security, score: 1.00} - {ref: solutions/igel/addon/90meter, score: 0.70} - {ref: solutions/endpoint-security/microsoft-defender-atp, score: 0.70}
{ "apiVersion": "soultec.ch/v1", "kind": "Solution", "metadata": { "name": "endpoint-security/crowdstrike-falcon", "locale": "en", "labels": { "capability/endpoint-security": "2.85", "capability/security": "2.01", "vendor/crowdstrike": "4.36" }, "annotations": { "source": "src/content/solutions/en/endpoint-security/crowdstrike-falcon.md", "route": "/en/solutions/endpoint-security/crowdstrike-falcon/", "schema": "/nerd/schema/solutions.json", "markdown": "/en/solutions/endpoint-security/crowdstrike-falcon.md" } }, "spec": { "title": "CrowdStrike Falcon", "tags": [ "endpoint-security", "security" ], "vendors": [ "crowdstrike" ], "summary": "Endpoint detection and response from CrowdStrike. A lean sensor on the device, analysis in the cloud, and a platform that grows by module.", "photoNeed": "A security console on screen with real alerts in it, being triaged", "stub": false, "draft": false, "kind": "product", "addon": false, "status": "current", "practice": "CrowdStrike replaces Carbon Black as our EDR product. We no longer support Carbon Black.\n", "practiceReview": false }, "sections": [ { "heading": "

What it is

",
"body": "Falcon is CrowdStrike's endpoint platform. A lean sensor supplies the events from the\ndevice; the analysis runs in the vendor's cloud. What gets judged is behaviour rather than\nfiles: not \"do I know this signature\", but \"why is this process reading another one's\nmemory\"." }, { "heading": "

What it is for

",
"body": "Estates that choose their endpoint security independently of the rest of the stack. Falcon\nties you to no platform licence and covers Windows, macOS and Linux with the same sensor.\n\nThe second point is growth: EDR is one module of several. Identity protection, cloud\nworkloads and threat intelligence come out of the same console when they are needed." }, { "heading": "

What to watch

",
"body": "The modules are licensed individually, and the feature set depends on the package you\nbought. What a quote calls \"Falcon\" is therefore not always the same Falcon.\n\nAnd as with any EDR: the recording is worth as much as the team looking at it. Where there\nis none, managed detection and response belongs in the plan from day one." } ], "status": { "corpus": 309, "services": [ { "ref": "services/modern-workplace", "score": "0.82" }, { "ref": "services/security", "score": "0.43" }, { "ref": "services/network", "score": "0.20" } ], "posts": [ { "ref": "posts/how-to-build-a-test-environment-for-opswat-metadefender-managed-file-transfer", "score": "0.44" }, { "ref": "posts/how-to-secure-your-dmz-with-a-proxy", "score": "0.44" }, { "ref": "posts/exagrid", "score": "0.35" }, { "ref": "posts/vmware-security-advisory", "score": "0.29" }, { "ref": "posts/vmware-security-advisory-vmsa-2024-0012", "score": "0.29" }, { "ref": "posts/vmware-security-advisory-vmsa-2022-0030", "score": "0.29" } ], "neighbours": [ { "ref": "solutions/endpoint-security", "score": "1.00" }, { "ref": "solutions/igel/addon/90meter", "score": "0.70" }, { "ref": "solutions/endpoint-security/microsoft-defender-atp", "score": "0.70" } ] }}
apiVersion = "soultec.ch/v1"kind = "Solution"[metadata]name = "endpoint-security/crowdstrike-falcon"locale = "en"[metadata.labels]"capability/endpoint-security" = "2.85""capability/security" = "2.01""vendor/crowdstrike" = "4.36"[metadata.annotations]source = "src/content/solutions/en/endpoint-security/crowdstrike-falcon.md"route = "/en/solutions/endpoint-security/crowdstrike-falcon/"schema = "/nerd/schema/solutions.json"markdown = "/en/solutions/endpoint-security/crowdstrike-falcon.md"[spec]title = "CrowdStrike Falcon"tags = ["endpoint-security", "security"]vendors = ["crowdstrike"]summary = "Endpoint detection and response from CrowdStrike. A lean sensor on the device, analysis in the cloud, and a platform that grows by module."photoNeed = "A security console on screen with real alerts in it, being triaged"stub = falsedraft = falsekind = "product"addon = falsestatus = "current"practice = '''CrowdStrike replaces Carbon Black as our EDR product. We no longer support Carbon Black.'''practiceReview = false[[sections]]heading = "

What it is

"
body = '''Falcon is CrowdStrike's endpoint platform. A lean sensor supplies the events from thedevice; the analysis runs in the vendor's cloud. What gets judged is behaviour rather thanfiles: not "do I know this signature", but "why is this process reading another one'smemory".'''[[sections]]heading = "

What it is for

"
body = '''Estates that choose their endpoint security independently of the rest of the stack. Falconties you to no platform licence and covers Windows, macOS and Linux with the same sensor.The second point is growth: EDR is one module of several. Identity protection, cloudworkloads and threat intelligence come out of the same console when they are needed.'''[[sections]]heading = "

What to watch

"
body = '''The modules are licensed individually, and the feature set depends on the package youbought. What a quote calls "Falcon" is therefore not always the same Falcon.And as with any EDR: the recording is worth as much as the team looking at it. Where thereis none, managed detection and response belongs in the plan from day one.'''[status]corpus = 309[[status.services]]ref = "services/modern-workplace"score = "0.82"[[status.services]]ref = "services/security"score = "0.43"[[status.services]]ref = "services/network"score = "0.20"[[status.posts]]ref = "posts/how-to-build-a-test-environment-for-opswat-metadefender-managed-file-transfer"score = "0.44"[[status.posts]]ref = "posts/how-to-secure-your-dmz-with-a-proxy"score = "0.44"[[status.posts]]ref = "posts/exagrid"score = "0.35"[[status.posts]]ref = "posts/vmware-security-advisory"score = "0.29"[[status.posts]]ref = "posts/vmware-security-advisory-vmsa-2024-0012"score = "0.29"[[status.posts]]ref = "posts/vmware-security-advisory-vmsa-2022-0030"score = "0.29"[[status.neighbours]]ref = "solutions/endpoint-security"score = "1.00"[[status.neighbours]]ref = "solutions/igel/addon/90meter"score = "0.70"[[status.neighbours]]ref = "solutions/endpoint-security/microsoft-defender-atp"score = "0.70"
<?xml version="1.0" encoding="UTF-8"?><manifest kind="Solution"> <apiVersion>soultec.ch/v1</apiVersion> <metadata> <name>endpoint-security/crowdstrike-falcon</name> <locale>en</locale> <labels> <entry key="capability/endpoint-security">2.85</entry> <entry key="capability/security">2.01</entry> <entry key="vendor/crowdstrike">4.36</entry> </labels> <annotations> <source>src/content/solutions/en/endpoint-security/crowdstrike-falcon.md</source> <route>/en/solutions/endpoint-security/crowdstrike-falcon/</route> <schema>/nerd/schema/solutions.json</schema> <markdown>/en/solutions/endpoint-security/crowdstrike-falcon.md</markdown> </annotations> </metadata> <spec> <title>CrowdStrike Falcon</title> <tags> <item>endpoint-security</item> <item>security</item> </tags> <vendors> <item>crowdstrike</item> </vendors> <summary>Endpoint detection and response from CrowdStrike. A lean sensor on the device, analysis in the cloud, and a platform that grows by module.</summary> <photoNeed>A security console on screen with real alerts in it, being triaged</photoNeed> <stub>false</stub> <draft>false</draft> <kind>product</kind> <addon>false</addon> <status>current</status> <practice>CrowdStrike replaces Carbon Black as our EDR product. We no longer support Carbon Black. </practice> <practiceReview>false</practiceReview> </spec> <sections> <section> <heading>

What it is

</heading>
<body>Falcon is CrowdStrike's endpoint platform. A lean sensor supplies the events from thedevice; the analysis runs in the vendor's cloud. What gets judged is behaviour rather thanfiles: not "do I know this signature", but "why is this process reading another one'smemory". </body> </section> <section> <heading>

What it is for

</heading>
<body>Estates that choose their endpoint security independently of the rest of the stack. Falconties you to no platform licence and covers Windows, macOS and Linux with the same sensor.The second point is growth: EDR is one module of several. Identity protection, cloudworkloads and threat intelligence come out of the same console when they are needed. </body> </section> <section> <heading>

What to watch

</heading>
<body>The modules are licensed individually, and the feature set depends on the package youbought. What a quote calls "Falcon" is therefore not always the same Falcon.And as with any EDR: the recording is worth as much as the team looking at it. Where thereis none, managed detection and response belongs in the plan from day one. </body> </section> </sections> <status> <corpus>309</corpus> <services> <item> <ref>services/modern-workplace</ref> <score>0.82</score> </item> <item> <ref>services/security</ref> <score>0.43</score> </item> <item> <ref>services/network</ref> <score>0.20</score> </item> </services> <posts> <item> <ref>posts/how-to-build-a-test-environment-for-opswat-metadefender-managed-file-transfer</ref> <score>0.44</score> </item> <item> <ref>posts/how-to-secure-your-dmz-with-a-proxy</ref> <score>0.44</score> </item> <item> <ref>posts/exagrid</ref> <score>0.35</score> </item> <item> <ref>posts/vmware-security-advisory</ref> <score>0.29</score> </item> <item> <ref>posts/vmware-security-advisory-vmsa-2024-0012</ref> <score>0.29</score> </item> <item> <ref>posts/vmware-security-advisory-vmsa-2022-0030</ref> <score>0.29</score> </item> </posts> <neighbours> <item> <ref>solutions/endpoint-security</ref> <score>1.00</score> </item> <item> <ref>solutions/igel/addon/90meter</ref> <score>0.70</score> </item> <item> <ref>solutions/endpoint-security/microsoft-defender-atp</ref> <score>0.70</score> </item> </neighbours> </status></manifest>
Solution · CrowdStrike

CrowdStrike Falcon

Endpoint detection and response from CrowdStrike. A lean sensor on the device, analysis in the cloud, and a platform that grows by module.

Topics Endpoint Security 2.85 Security 2.01
Vendors CrowdStrike 4.36
03Services
06Posts
02Capabilities
309Corpus

What it is

Falcon is CrowdStrike’s endpoint platform. A lean sensor supplies the events from the device; the analysis runs in the vendor’s cloud. What gets judged is behaviour rather than files: not “do I know this signature”, but “why is this process reading another one’s memory”.

What it is for

Estates that choose their endpoint security independently of the rest of the stack. Falcon ties you to no platform licence and covers Windows, macOS and Linux with the same sensor.

The second point is growth: EDR is one module of several. Identity protection, cloud workloads and threat intelligence come out of the same console when they are needed.

What to watch

The modules are licensed individually, and the feature set depends on the package you bought. What a quote calls “Falcon” is therefore not always the same Falcon.

And as with any EDR: the recording is worth as much as the team looking at it. Where there is none, managed detection and response belongs in the plan from day one.

What we do with it

CrowdStrike replaces Carbon Black as our EDR product. We no longer support Carbon Black.

Posts about it

Who works with it

Do you work with this? Take a look at our open roles.